Skip to content
PHISHNOVA
All resources
Compliance / India·September 7, 2026·7 min read

DPDP Act 2023 and security awareness: what you actually have to show

DPDP moves awareness training out of “nice to have” and into a control an auditor expects evidence for. Here is what that evidence looks like, where programs fall short, and a checklist to self-assess before someone else does.


India's Digital Personal Data Protection Act, 2023 is reshaping how organizations think about data-handling obligations. One of its quieter downstream effects is pulling security-awareness training out of the "nice to have" category and into something regulators, auditors and — increasingly — your own customers expect to see evidence of.

This is educational, not legal advice. It maps common DPDP-era expectations onto the awareness program you already need. Confirm your specific obligations with counsel.

Why DPDP raises the bar on awareness specifically

DPDP is about protecting personal data and holding organizations accountable for how it is handled. A meaningful share of personal-data incidents do not begin with a sophisticated technical exploit — they begin with an employee acting on a convincing but fraudulent request: a spoofed internal email, a vishing call posing as IT, a WhatsApp message that looks like it came from a vendor. Untrained employees are, in practice, a control gap in the data-protection chain, and that is exactly the kind of gap a DPDP-oriented audit is designed to surface.

Two other forces landed at the same time. CERT-In recorded a 300% increase in UPI-related fraud complaints between 2023 and 2025, and the RBI's FY2024–25 Annual Report shows a 34% year-on-year rise in digital-payment fraud — most of it arriving by SMS, WhatsApp and voice rather than email. And security questionnaires now routinely ask whether you run phishing simulations, and want evidence rather than a yes.

What "evidence" actually needs to look like

A general sense that "we do some training" is not evidence. What reviewers want to see:

  • A documented program, not an ad hoc effort. Who is enrolled, on what cadence, covering which threat types — mapped to the attacks relevant to your sector and region rather than a generic global template set.
  • Completion and outcome tracking, not "training was offered." Records of who completed what and when, how they performed, and a trend over time rather than a single snapshot.
  • An audit trail tied to specific frameworks. ISO 27001:2022 and DPDP both expect audit-log evidence: dates, participants, outcomes, and a mapping back to the control being satisfied.
  • A response process, not just training. What happens when someone reports a suspected phish, or falls for a simulation — is there a documented coaching or escalation step, or does it end at "noted"?

Where programs trip up

Two failure modes, both common in first-time programs.

Doing the training but not documenting it well enough to prove it. A session that happened but left no structured record is functionally invisible in a review. If it is not logged with who, what and when, it is hard to distinguish from not having happened.

Treating one point-in-time push as sufficient. A single all-hands session satisfies very little of what a "reasonable safeguards" standard implies. The expectation is ongoing and current, not a historical event.

The readiness checklist

Use this to self-assess before someone else does.

  • Every employee who handles personal data has been tested against email, SMS and voice lures — not email alone.
  • Security-awareness training has a named owner, not an informal duty.
  • There is a recurring cadence across at least email and one other channel relevant to your sector.
  • Training completion is logged per person, with dates and outcomes — not just attendance.
  • You measure risk over time (a culture or risk score), not a single click rate.
  • Failed simulations trigger coaching tied to the specific lure, recorded as evidence.
  • Your audit log maps to DPDP Act 2023 and ISO 27001:2022 and can be exported on request.
  • You can state where employee data goes when any AI feature runs — and self-host if your risk posture requires it.
  • You can produce the report on demand, not after weeks of manual compilation.

If you cannot tick most of these, you have a documentation gap before you have a security gap. Both are addressable, and the documentation one is cheaper.

Build the trail as you go, not afterwards

The efficient approach is a platform that produces the audit trail as a byproduct of running the program, rather than a separate documentation exercise bolted on under deadline pressure. PhishNova's audit-log mapping is built against ISO 27001:2022 and DPDP Act 2023, alongside scheduled reports and department- and manager-scoped analytics, so the evidence a review asks for is close to what the platform already produces for day-to-day management.

One point that matters more in India than most places: you should be able to say exactly where employee data goes when an AI feature runs. PhishNova's AI provider defaults to a local model inside your own environment, and the platform self-hosts via Docker, so for a data-residency-bound organization the answer can simply be "it does not leave".

Honest framing: these capabilities make an audit faster and better-evidenced. They document readiness; they do not by themselves make an organization compliant. Compliance is a determination about your whole posture, not a single tool.

The next step

Run a baseline. A multi-channel risk assessment quantifies where your workforce stands today and produces the first artifact for your evidence file — and it costs you nothing to find out.

---

*Sources: Digital Personal Data Protection Act, 2023; ISO/IEC 27001:2022 (A.6.3); CERT-In UPI-fraud reporting 2023–2025; RBI Annual Report FY2024–25. India fraud figures reached this article through secondary aggregation — verify against primary sources before high-stakes external use.*

Run a program that keeps pace.

See PhishNova mirror this week’s real attacks on your own attack surface.

Book a demo